CVE · High

CVE-2025-47445 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47445 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27 Relative Path Traversal High 7.5 < 4.0.27 4.0.27 2025-05-14

CVE-2025-47445

A flaw exists in the way Eventin handles file paths, allowing an attacker to access files outside of their intended directory by manipulating path information in requests to the wp-event-solution component of Arraytics Eventin. This vulnerability impacts versions of Eventin from unavailable up to and including 4.0.26.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.